CVE-2024-10787: LA-Studio Element Kit for Elementor <= 1.4.4 - Authenticated (Contributor+) Post Disclosure
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.4 via the 'elementor-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from private and draft posts created by Elementor that they should not have access to.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10787?
CVE-2024-10787 has a moderate severity rating due to potential information exposure risks.
How do I fix CVE-2024-10787?
To fix CVE-2024-10787, update the LA-Studio Element Kit for Elementor plugin to version 1.4.5 or later.
Who is affected by CVE-2024-10787?
All users of the LA-Studio Element Kit for Elementor plugin for WordPress up to version 1.4.4 are affected by CVE-2024-10787.
What kind of information is exposed in CVE-2024-10787?
CVE-2024-10787 allows for the potential unauthorized access to sensitive post content due to insufficient restrictions.
Is there a way to mitigate the risks of CVE-2024-10787 without updating?
There are no effective workarounds or mitigations for CVE-2024-10787 other than updating to a secure version of the plugin.